Broken Link Checker <= 1.11.16 - Authenticated (Admin+) PHAR Deserialization

2022-07-18 00:00
Rasoul Jahanshahi

Strategic Overview

Status
Patched in 1.11.17
Affected PluginBroken Link Checker
Affected Version<= 1.11.16
CVSS7.2High
CVECVE-2022-2438
View all Broken Link Checker vulnerabilities

Vulnerability Overview

The Broken Link Checker plugin for WordPress is vulnerable to deserialization of untrusted input via the '$log_file' value in versions up to, and including 1.11.16. This makes it possible for authenticated attackers with administrative privileges and above to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.

Technical Analysis

REMEDIATION: Update to version 1.11.17, or a newer patched version --- IDENTIFIER: CWE-502 (Deserialization of Untrusted Data) The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C